• Coffee forensics — Reconstructing data in IoT devices running Contiki OS 

      Sandvik, Jens-Petter; Franke, Katrin; Abie, Habtamu; Årnes, Andrè (Peer reviewed; Journal article, 2021)
      The ability to examine evidence and reconstruct files from novel IoT operating systems, such as Contiki with its Coffee File System, is becoming vital in digital forensic investigations. Two main challenges for an investigator ...
    • Quantifying data volatility for IoT forensics with examples from Contiki OS 

      Sandvik, Jens-Petter; Franke, Katrin; Abie, Habtamu; Årnes, Andrè (Journal article; Peer reviewed, 2022)
      Forensic investigations are often conducted under limited resource availability such as time, equipment, and people. As data acquisition is resource-demanding already, a higher emphasis needs to be put on prioritizing the ...
    • The reliability of clocks as digital evidence under low voltage conditions 

      Sandvik, Jens-Petter; Årnes, Andrè (Journal article; Peer reviewed, 2018)
      Battery powered electronic devices like mobile phones are abundant in the world today, and such devices are often subject to digital forensic examinations. In this paper, we show that the assumptions that clocks are close ...
    • Towards a Generic Approach of Quantifying Evidence Volatility in Resource Constrained Devices 

      Sandvik, Jens-Petter; Franke, Katrin; Årnes, Andrè (Chapter, 2021)
      Forensic investigations of the Internet of Things (IoT) is often assumed to be a combination of existing cloud, network, and device forensics. Resource constraints in many of the peripheral things, however, are affecting ...